CVE-2024-13134

A vulnerability, which was classified as critical, was found in ZeroWdd studentmanager 1.0. Affected is the function addTeacher/editTeacher of the file src/main/Java/com/wdd/studentmanager/controller/TeacherController. java. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/ZeroWdd/studentmanager/issues/16 Not Applicable
https://github.com/ZeroWdd/studentmanager/issues/16#issue-2755347097 Not Applicable
https://vuldb.com/?ctiid.290208 Permissions Required VDB Entry
https://vuldb.com/?id.290208 Third Party Advisory VDB Entry
https://vuldb.com/?submit.467916 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:zerowdd:studentmanager:1.0:*:*:*:*:*:*:*

History

10 Oct 2025, 17:41

Type Values Removed Values Added
CPE cpe:2.3:a:zerowdd:studentmanager:1.0:*:*:*:*:*:*:*
First Time Zerowdd
Zerowdd studentmanager
References () https://github.com/ZeroWdd/studentmanager/issues/16 - () https://github.com/ZeroWdd/studentmanager/issues/16 - Not Applicable
References () https://github.com/ZeroWdd/studentmanager/issues/16#issue-2755347097 - () https://github.com/ZeroWdd/studentmanager/issues/16#issue-2755347097 - Not Applicable
References () https://vuldb.com/?ctiid.290208 - () https://vuldb.com/?ctiid.290208 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.290208 - () https://vuldb.com/?id.290208 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.467916 - () https://vuldb.com/?submit.467916 - Third Party Advisory, VDB Entry
Summary
  • (es) Se ha encontrado una vulnerabilidad clasificada como crítica en ZeroWdd studentmanager 1.0. La función addTeacher/editTeacher del archivo src/main/Java/com/wdd/studentmanager/controller/TeacherController.java se ve afectada. La manipulación del argumento file permite la carga sin restricciones. Es posible lanzar el ataque de forma remota. El exploit ha sido divulgado al público y puede ser utilizado.

05 Jan 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-05 08:15

Updated : 2025-10-10 17:41


NVD link : CVE-2024-13134

Mitre link : CVE-2024-13134

CVE.ORG link : CVE-2024-13134


JSON object : View

Products Affected

zerowdd

  • studentmanager
CWE
CWE-284

Improper Access Control

CWE-434

Unrestricted Upload of File with Dangerous Type